Vealth · Security disclosure
Found something? Tell us.
This is the plain-language version of our security.txt file. Same facts, same commitments, written for a person instead of a scanner. If the two ever disagree, security.txt is the one that governs; this page exists so nobody has to read RFC 9116 to find that out.
How to report
Email [email protected]. Say what you found, where, and how to reproduce it. If you have a proof-of-concept, include it; we would rather see it than guess at it. You do not need to encrypt the email or use any special format. If your tooling reads machine-readable records instead, the same contact and an expiry date live at /.well-known/security.txt (RFC 9116).
What's in scope
vealth.net and its public API surfaces: /labor, /.well-known, and /paid.
Also in scope: the Ecological Work Protocol contracts. Settlement and claim paths are what we care most about.
- EWP on Base mainnet (chain 8453):
0x76c17C51336BE7B39F5164802e08b9811477A14B - EWP on Robinhood mainnet (chain 4663):
0x5cB9ae2E3470B9E8f1aa4C071Db7ce6377061a9F
Verify either contract independently before relying on an address: read it directly from the chain, or from /is-this-safe.html, whose Base contract claim is checked live against eth_getCode in your own browser, not asserted by this page.
What's out of scope
Denial of service, volumetric testing, social engineering, and anything requiring physical access. Please do not run load tests or automated scanners that could degrade the service for other people using it; a handful of careful requests is plenty to demonstrate almost anything.
What to expect
We are a small team, not a security desk. We read every report ourselves. We will tell you what we are doing about it. We will credit you publicly unless you ask us not to.
We do not run a paid bounty, and we are not going to pretend otherwise by dressing this page up like one. If that matters to you before you spend real time on this, better to know now.
We are not going to promise a response-time SLA we cannot actually back with a small team. What we can promise is that a real person reads the email, not a form that disappears into a queue.
We build this for other teams too
Vealth runs on Claude Code as an always-on provisioner, and this disclosure page, the live posture checks, and the visitor-run safety proof it links to are the kind of thing that provisioner builds. We compose the same honest, evidence-carrying security posture for other sites, not only our own. If that is useful to you, the same address reaches us: [email protected]. No outreach from us either way; this stays here for whoever comes looking.
The full security program · Run the safety checks · Read the raw security.txt